Gateway eSIM Credential Management for Resource-Constrained IoT Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Resource-constrained client devices, such as sensor and actuator devices, lack the capability to store and manage credentials for secure communication with application servers, as they have limited processing power and no secure storage or user interface.

Innovation Solution

A method where a gateway requests, receives, and stores an electronically transferable subscriber identity module (eSIM) associated with the client device, allowing the gateway to provide credentials for authentication and secure communication without the need for the client device to manage secure storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If client devices store credentials locally for secure communication, then authentication and secure communication capabilities are improved, but device complexity and security requirements increase significantly

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecure storage requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the credential storage function from the client device and relocates it to the gateway. The gateway downloads eSIM credentials from the HSS and stores them in its own secure storage, while client devices only retain minimal identifiers. This extraction resolves the contradiction by maintaining authentication capability while eliminating the need for secure storage in constrained devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The gateway acts as an intermediary between the client device and the application server. It holds the credentials in secure storage and presents them to the server on behalf of the client device during authentication. This intermediary role allows the client device to authenticate without ever possessing the actual credentials, resolving the contradiction between authentication capability and secure storage requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If client devices handle credential management, then authentication control is improved, but processing power and resource requirements increase

Engineering Contradiction:
Improveauthentication controlVSAvoidprocessing power requirement
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent extracts the credential management function from the client device and consolidates it at the gateway. The gateway performs all credential operations including downloading from HSS, secure storage, and presentation to servers. Client devices only need to provide minimal identifiers and receive authentication results, dramatically reducing their processing requirements while maintaining authentication control.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The gateway provides self-service credential management for multiple client devices. It automatically downloads, stores, and manages credentials without requiring each client device to have independent credential management capabilities. This centralizes the processing burden on the gateway while freeing client devices from complex authentication control tasks.

Inventive Principle:
Principle #25Self-service

3Productivity

If multiple client devices share a gateway, then resource utilization is improved, but credential management complexity increases

Engineering Contradiction:
Improveresource utilizationVSAvoidcredential management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The gateway is designed as a universal credential management platform that serves multiple client devices with different capabilities. It implements a unified credential management system that handles diverse authentication scenarios (3GPP credentials, EAP-TLS, certificate-based authentication) through a single infrastructure, resolving the contradiction by providing multi-functional credential management that scales with the number of client devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The gateway creates and manages separate credential instances for each client device in its database, associating each eSIM with the appropriate client device identifier. This copying approach allows the gateway to serve multiple clients with individualized credentials while maintaining a centralized management system, thus improving resource utilization without proportionally increasing complexity.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11115501B2Gateway, client device and methods for facilitating communication between a client device and an application server
Publication Date: 2021.09.07 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11115501B2 patent drawing
  • US11115501B2 patent drawing
  • US11115501B2 patent drawing

AI summary

It is presented a method, executed in a gateway, the gateway being arranged to facilitate communication between a client device and an application server. The method comprises the steps of: sending a request for an electronically transferable subscriber identity module, the request comprising an identifier based on an identity of the client device; receiving a response indicating that an electronically transferable subscriber identity module, generated based on the identifier, is available; downloading the electronically transferable subscriber identity; and storing the electronically transferable subscriber identity module with an association to the client device, along with any previously stored electronically transferable subscriber identity modules. A corresponding gateway, computer program and computer program product are also presented.